Medium severity6.1NVD Advisory· Published Jul 9, 2022· Updated Jun 17, 2026
CVE-2022-2353
CVE-2022-2353
Description
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
microweber/microweberPackagist | < 1.2.20 | 1.2.20 |
Affected products
3cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microweber:microweber:*:*:*:*:*:*:*:*range: <1.2.20
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/microweber/microweber/commit/79c6914bab8c9da07ac950fda17648d08c68b130nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/7782c095-9e8c-48b0-a7f5-3a8f52e8af52nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gmh3-x5w7-jg5mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-2353ghsaADVISORY
News mentions
0No linked articles in our index yet.